CVE-2018-17282: Null Pointer Dereference
Published Sep 20, 2018
·Updated
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Sep 20, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Sep 24, 2018
Data Sourced
via Red Hat·09:33 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-17282?
CVE-2018-17282 has been classified as a high-severity vulnerability due to the potential for denial of service from a NULL pointer dereference.
2
How does CVE-2018-17282 affect Exiv2?
CVE-2018-17282 affects Exiv2 v0.26 by introducing a NULL pointer dereference that can lead to application crashes.
3
How do I fix CVE-2018-17282?
To fix CVE-2018-17282, upgrade Exiv2 to a version later than v0.26 where this vulnerability has been addressed.
4
What versions of Exiv2 are vulnerable to CVE-2018-17282?
The vulnerable version specified in CVE-2018-17282 is Exiv2 v0.26.
5
Can CVE-2018-17282 be exploited remotely?
CVE-2018-17282 can potentially be exploited remotely if malicious input is processed by Exiv2 v0.26.